Application Security Engineer

Saviance

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field.
  • 3-5 years of experience in application security, DevSecOps, or security-focused software engineering.
  • Hands-on experience with SonarQube for static code analysis.
  • Experience with SAST, DAST, SCA, and IAST tooling in CI/CD pipelines.
  • Knowledge of the OWASP Top 10 and secure coding practices in languages like Java, C#, Python, and JavaScript.
  • Familiarity with penetration testing and vulnerability management processes.
  • Understanding of healthcare compliance frameworks like HIPAA.

Responsibilities

  • Implement and manage static and dynamic code analysis tools like SonarQube.
  • Perform penetration tests and vulnerability assessments on applications.
  • Develop and maintain a structured remediation program for security findings.
  • Evolve the organization's SDLC into a Secure SDLC by embedding security principles.
  • Integrate secure coding practices and provide guidance to development teams.
  • Generate regular reports on application security initiatives and risk assessments.
  • Collaborate with auditors and draft necessary security policies.

Benefits

  • Remote work opportunity within the United States.
  • Opportunity to work at a leading organization in clinical genetic testing.
  • Contribute to protecting highly sensitive patient data.
  • Engage in cross-functional collaboration to drive measurable risk reduction.
Full Job Description
Application Security Engineer

Location: Remote (United States)
Type of Role: Full-Time


Overview

An organization is seeking an Application Security Engineer to build and mature its application security program, embedding security across the software development lifecycle (SDLC) and championing Security by Design principles. As a leader in clinical genetic testing, the organization handles highly sensitive patient data across its web, API, and pipeline applications, and this role is central to protecting that data and reducing risk. The engineer will implement and manage static and dynamic code analysis tooling - including SonarQube and BURP - partner closely with engineering to remediate findings, and help close audit-identified gaps in secure coding, software composition analysis, and code review coverage. This role directly supports HIPAA compliance and organizational risk reduction; scope may evolve as organizational needs change.

Key Responsibilities
  • Implement and manage static and dynamic code analysis, integrating SonarQube (and complementary SAST/DAST/SCA tools) into CI/CD pipelines and check-in scans, and partner with engineering to triage and remediate findings.
  • Perform penetration tests and vulnerability assessments across web, API, and pipeline applications, and lead consistent, timely remediation of identified findings.
  • Develop and maintain a structured remediation program that addresses and resolves security findings quickly, consistently, and in priority order.
  • Evolve the organization's SDLC into a Secure SDLC (SSDLC) by embedding Security by Design and Privacy by Design principles at every stage.
  • Integrate secure coding practices with development teams, providing guidance, threat modeling, and secure architecture reviews for new features and releases.
  • Generate regular reports on the status of application security initiatives, vulnerability management, and risk assessments for technical and executive audiences.
  • Collaborate with auditors during internal and external audits, providing explanations, evidence, and documentation, and draft security policies and procedures as needed.
  • Partner cross-functionally with IT, Privacy, Compliance, and business units to support initiatives and drive measurable risk reduction.

Required Experience & Skills
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field - or an equivalent combination of education and experience.
  • Minimum of 3-5 years of experience in application security, DevSecOps, or software engineering with a security focus.
  • Hands-on experience with SonarQube for static code analysis and code quality/security gating.
  • Experience with SAST, DAST, SCA, and IAST tooling and integrating them into CI/CD pipelines.
  • Working knowledge of the OWASP Top 10, common attack vectors, and secure coding practices in languages such as Java, C#/.NET, Python, and JavaScript.
  • Familiarity with penetration testing, code review, and vulnerability management processes.
  • Understanding of compliance frameworks and regulations relevant to healthcare data, including HIPAA, NIST, and GDPR.
  • Excellent written and verbal communication skills, with the ability to translate technical risk for non-technical stakeholders and collaborate cross-functionally.
  • Detail-oriented, self-directed, and able to prioritize in a fast-moving environment.

Nice to Have
  • Relevant industry certifications such as OSCP, CSSLP, GWAPT, CISSP, or equivalent.
  • Experience securing web applications, APIs, and cloud-native/containerized workloads.
  • Knowledge of authentication and authorization frameworks (e.g., SAML, OAuth, OpenID Connect).
  • Prior experience in a healthcare, clinical laboratory, or other regulated (HIPAA/PHI) environment.

Similar Jobs

More Jobs at Saviance

More Information Technology Jobs

Find similar Application Security Engineer jobs: